Ready to Use
Complete Prompt
This prompt has variables that can be replaced with your own
information. Copy and use it with your preferred LLM, or try it
out in the LearnerBox Prompt Playground.
Act as a senior operational-risk and internal-control professional.
Develop an operational Risk and Control Self-Assessment and loss-event register using the information provided below.
Organization or process:
{{organization_process}}
Objectives and process map:
{{objectives_process_map}}
Risk information:
{{risk_information}}
Controls and evidence:
{{controls_evidence}}
Historical incidents and losses:
{{loss_events}}
Risk taxonomy and scoring policy:
{{risk_policy}}
Analysis requirements:
1. Define the process objectives, activities, owners, systems, inputs, outputs, and dependencies.
2. Identify risks using the approved taxonomy, including:
- people;
- process;
- systems;
- external events;
- fraud;
- cyber;
- legal;
- compliance;
- third party;
- data;
- model;
- business continuity; and
- financial reporting.
3. For each risk, document:
- event;
- cause;
- consequence;
- affected objective;
- owner;
- frequency;
- severity;
- velocity;
- detectability;
- interdependency; and
- emerging-risk indicators.
4. Assess inherent risk using approved scoring criteria.
5. Map preventive, detective, corrective, and directive controls.
6. Evaluate control design and operating effectiveness separately.
7. Identify key controls, compensating controls, control gaps, duplicate controls, and excessive manual dependency.
8. Calculate residual risk using the approved methodology.
9. Define key risk indicators, thresholds, data sources, owners, and escalation rules.
10. Structure a loss-event register containing:
- event date;
- discovery date;
- category;
- process;
- description;
- root cause;
- gross loss;
- recovery;
- net loss;
- near miss;
- control failure;
- remediation;
- owner; and
- closure evidence.
11. Link historical loss events and near misses to assessed risks and controls.
12. Develop action plans with priorities, owners, due dates, and evidence requirements.
13. Do not invent control evidence, incident facts, loss amounts, legal conclusions, or scoring thresholds.
14. Do not treat self-assessment as independent assurance.
Present the result as:
{{output_format}}
Include:
- process and objective summary;
- risk register;
- inherent-risk assessment;
- control inventory;
- design-effectiveness review;
- operating-effectiveness review;
- residual-risk matrix;
- key risk indicators;
- loss-event register;
- root-cause themes;
- remediation plan;
- escalation priorities; and
- governance recommendations.
Personalize the Template
Customization Variables
Replace each variable shown in double curly
brackets with accurate information from your
own professional context.
Example:
Example: Accounts payable process
Identify the business unit, legal entity, or end-to-end process being assessed.
Example:
Describe objectives, activities, owners, systems, inputs, outputs, dependencies, and handoffs.
A clear process map improves risk and control identification.
Example:
List known risks, emerging issues, regulatory concerns, dependencies, and prior assessments.
Use the organization’s approved risk taxonomy where available.
Example:
List controls, owners, frequency, evidence, testing results, exceptions, and remediation.
Separate documented control design from evidence of actual operation.
Example:
Provide incidents, near misses, dates, causes, losses, recoveries, controls, and actions.
Use verified event data and protect confidential personal information.
Example:
Paste approved categories, likelihood, impact, control, residual-risk, and escalation criteria.
The AI should apply the approved policy rather than inventing thresholds.
Choose the format required for assessment, documentation, or governance.
Complete RCSA report
Risk and control matrix
Loss-event register template
Operational-risk committee paper
What the AI Should Produce
Expected Output
🎯
A complete RCSA and loss-event framework containing process objectives, risks, controls, inherent and residual ratings, KRIs, incident links, root causes, remediation, and governance recommendations.
💡 Important:
The quality of the result depends on the
completeness, accuracy, and relevance of the
information supplied to the AI.
Prompt Profile
Prompt Characteristics
These characteristics describe the type of
thinking, customization, and output structure
involved in using this prompt effectively.
🧠
Reasoning Depth
Advanced
💡
Creativity
Moderate
🛠
Customization
High
📚
Output Structure
Highly Structured
🎓
Experience Level
Advanced
Learn Why It Works
Prompt Anatomy
This breakdown explains how the prompt’s major
components work together to guide the AI toward
a useful, reliable, and well-structured response.
💼
Role
Positions the AI as an operational-risk and internal-control specialist.
📄
Context
Defines process objectives, risks, controls, evidence, incidents, taxonomy, and scoring.
🎯
Task
Requires an RCSA, control assessment, KRI framework, and loss-event register.
🛡️
Constraints
Prevents invented evidence, incidents, losses, thresholds, legal conclusions, and assurance claims.
📚
Output Structure
Requires registers, matrices, ratings, KRIs, losses, remediation, and governance.
🔑
Input Variables
Organization, process map, risks, controls, loss events, policy, and output format.
🛡️
Responsible Professional Use
Review Before Applying the Output
AI-generated responses can contain errors,
omissions, unsupported assumptions, outdated
information, or recommendations that do not
reflect your jurisdiction or professional
context.
Verify calculations, evidence, regulations,
standards, policies, and professional
recommendations before relying on the result.
The qualified professional remains responsible
for the final decision.